<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Config Audit in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308222#M79988</link>
    <description>&lt;P&gt;I'm trying to rally the users for support so that palo will address the issue of the config auditor and make the tool work better to find changes. What is your experience with the tool? DO you see the same thing I am seeing. Would you like it to work better and more easily to find actual changes in the config&amp;nbsp;and not one induced by the programmers.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2020 12:16:37 GMT</pubDate>
    <dc:creator>MarkDufault</dc:creator>
    <dc:date>2020-01-28T12:16:37Z</dc:date>
    <item>
      <title>Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308132#M79972</link>
      <description>&lt;P&gt;Hi Everyone - I wanted to pose this question to the folks out there that may be feeling the same as I do about the way the config audit feature works. It is supposed to be a simple way to do a diff on config changes/deletes. I have found that palo seems to insert simicolons and braces throwing off the reporting and making it less than optimal for a tool that should be more simple. I am on v 8.1.6 and use panorama also, just fyi. I have heard some of the explanations as to why but it doesn't change the end game of the tool be less useful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case opened&amp;nbsp;Case#: 01355897.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The programming team that created and maintains the PAN-OS normally does not give information about its internal design in the interest of platform security.&lt;BR /&gt;The programming team does not share their software designs with the members of the technical support staff.&lt;BR /&gt;&lt;BR /&gt;I believe that the main reason for these changes is to consolidate disk space.&lt;BR /&gt;For example, a PA-200 can only have a maximum of 2500 address objects.&lt;BR /&gt;Firewall administrators can add and delete address objects over a period of time which can cause gaps in the address objects database.&lt;BR /&gt;In order to keep the database as small as possible,&lt;BR /&gt;the firewall might perform cleanup procedures which might include moving addresses that are high in the list into sections of the database where other addresses were deleted previously.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2020 18:11:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308132#M79972</guid>
      <dc:creator>MarkDufault</dc:creator>
      <dc:date>2020-01-27T18:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308214#M79986</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20268"&gt;@MarkDufault&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What is your question exactly ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 28 Jan 2020 09:45:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308214#M79986</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-01-28T09:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308222#M79988</link>
      <description>&lt;P&gt;I'm trying to rally the users for support so that palo will address the issue of the config auditor and make the tool work better to find changes. What is your experience with the tool? DO you see the same thing I am seeing. Would you like it to work better and more easily to find actual changes in the config&amp;nbsp;and not one induced by the programmers.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 12:16:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308222#M79988</guid>
      <dc:creator>MarkDufault</dc:creator>
      <dc:date>2020-01-28T12:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308233#M79990</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20268"&gt;@MarkDufault&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Honestly, I don't see this issue of added brackets or semicolons.&amp;nbsp;&amp;nbsp; Blank lines I see yes ... when configuration is removed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For me the Config Audit reflects the changes perfectly.&lt;/P&gt;
&lt;P&gt;Green = Added new configuration&lt;/P&gt;
&lt;P&gt;Red = Removed configuration&lt;/P&gt;
&lt;P&gt;Yellow = Changed configuration&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nowhere do I see added semicolons or brackets in the Config Audit, unless of course it is required by the XML formatting by adding new config.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The blank lines I do see in the config audit when configuration is removed.&amp;nbsp; But if you look at the numbering going from 948 to 949 in the&amp;nbsp; screeshot below... you'll know that there are no actual lines there... it's just to visualize the changes made.&amp;nbsp; Exporting the config should have no empty lines there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="removed config" style="width: 874px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23669i34DDDA625D6C3F07/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-01-28_14-27-48.png" alt="removed config" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;removed config&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or are you seeing this behaviour only when performing certain changes on the config (removing and adding address objects for example ... I haven't tested that) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe more people can share their experience.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;
&lt;DIV id="ConnectiveDocSignExtentionInstalled" data-extension-version="1.0.4"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 28 Jan 2020 13:41:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308233#M79990</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2020-01-28T13:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308241#M79992</link>
      <description>&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Here would be my example:&lt;/P&gt;&lt;P&gt;These are riddled all over the place making it difficult to find the REAL changes.&lt;/P&gt;&lt;P&gt;Also, I would add that my version of code is not changing, so it is the same version on left and right panes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23670iEC55EF10088649C1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 13:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308241#M79992</guid>
      <dc:creator>MarkDufault</dc:creator>
      <dc:date>2020-01-28T13:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308244#M79993</link>
      <description>&lt;P&gt;Sorry, I should have included more lines for context:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23671iF90813C83DA12B9E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 13:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308244#M79993</guid>
      <dc:creator>MarkDufault</dc:creator>
      <dc:date>2020-01-28T13:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308391#M80004</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20268"&gt;@MarkDufault&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is due to mixing configuration methods (IE: Using the CLI and the GUI, mixing CLI with XML/API). If you want this to remain static, pick a configuration method and dedicate changes to only utilize that method.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2020 22:45:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308391#M80004</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-01-28T22:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308506#M80027</link>
      <description>&lt;P&gt;We don't do changes very often via CLI. And these diffs are not related to that since we have not done any recently.&lt;/P&gt;&lt;P&gt;We do changes via panorama. We have dynamic EDL's, Minemeld, etc...&lt;/P&gt;&lt;P&gt;I don't know the inner working of how the above work, and they may cause some issue.&lt;/P&gt;&lt;P&gt;We also apply updates via panorama by schedule.&lt;/P&gt;&lt;P&gt;It is a real pain in the neck to try to find where the changes are when the config is riddled with yellow like the previous snippet.&lt;/P&gt;&lt;P&gt;There are too many for me to include them all in this forum but they are all similar to what I pasted in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If others have similar experiences, please chime in, I would really like palo to take note and see if they can come up with a fix.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 15:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308506#M80027</guid>
      <dc:creator>MarkDufault</dc:creator>
      <dc:date>2020-01-29T15:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308508#M80028</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20268"&gt;@MarkDufault&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The difference that you are seeing has to do with how the underlying XML configuration is actually specified; if you would export the configuration versions you could visually see what the difference is in the XML. Usually, this is caused by changing how you are making changes, but even the order of operations of how you modify some of these settings in the GUI can cause minor differences like this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 15:23:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/308508#M80028</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-01-29T15:23:29Z</dc:date>
    </item>
    <item>
      <title>Re: Config Audit</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/390359#M90707</link>
      <description>&lt;P&gt;Having worked with PAN devices for years now I can add my voice that this is a constant and challenging problem. Despite the fact that the PAN can't seem to write consistent XML, it SHOULD be able to. Format differences, re-ordering elements, different syntax between the WebGUI and CLI - it all amounts to poor handling. If you've never seen this issue completely mangle a config audit, you haven't worked with large enough configs for it to cause literally hours of extra work. Please don't pretend something isn't an issue because it's never affected you.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 19:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/config-audit/m-p/390359#M90707</guid>
      <dc:creator>PaulMarroquin</dc:creator>
      <dc:date>2021-03-10T19:37:25Z</dc:date>
    </item>
  </channel>
</rss>

